Description
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service.
Published: 2026-07-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA Triton Inference Server for Linux contains a flaw that allows an attacker to trigger an uncaught exception during inference processing. This can cause the server to crash and become unavailable, compromising service availability but not directly exposing data or allowing code execution. The weakness corresponds to CWE‑248 handling oversight that leads to application instability.

Affected Systems

The vulnerability affects NVIDIA Triton affected releases are not enumerated in the advisory, so all current Linux builds may be susceptible until a patch is issued.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact rating for denial of service, while the EPSS score indicates a very low likelihood of exploitation and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves sending malicious or malformed inference requests over the network, allowing a remote attacker to trigger the exception.

Generated by OpenCVE AI on July 31, 2026 at 05:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade to the latest release of Triton Inference Server that corrects the exception handling flaw.
  • If no patch is available yet, limit external access to the inference endpoint to trusted clients only, and consider enforcing network segmentation or firewall rules to isolate the service.
  • Enable detailed logging to capture uncaught exception events and review logs regularly for anomalous request patterns to detect abuse.

Generated by OpenCVE AI on July 31, 2026 at 05:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Uncaught Exception in NVIDIA Triton Inference Server Causes Denial of Service

Wed, 29 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Uncaught Exception Causing Denial of Service in NVIDIA Triton Inference Server

Sat, 25 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Uncaught Exception Causing Denial of Service in NVIDIA Triton Inference Server

Mon, 20 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Uncaught Exception in NVIDIA Triton Inference Server

Thu, 16 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Uncaught Exception in NVIDIA Triton Inference Server

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia triton Inference Server
Vendors & Products Nvidia
Nvidia triton Inference Server

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service.
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Nvidia Triton Inference Server
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-07-15T14:12:52.500Z

Reserved: 2026-05-19T19:55:38.728Z

Link: CVE-2026-47480

cve-icon Vulnrichment

Updated: 2026-07-15T14:12:48.229Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:15:03Z

Weaknesses